Chapter 2 of 425–35% of exam

Area II: Assessing Risk and Developing a Planned Response

This area follows planning from the overall strategy to a risk-based plan: understanding the entity and its controls, setting materiality, assessing the risk of material misstatement due to fraud or error, and deciding how to respond. It also covers using the work of others and several specific risk areas, including laws and regulations, estimates, related parties, and the Uniform Guidance thresholds that trigger a single audit.

Planning and understanding the entity

The overall audit strategy sets the scope, timing, and direction of the audit, and the audit plan turns it into specific risk assessment and further procedures. Understanding the entity covers external factors such as industry, regulation, and the economy, and internal factors such as ownership, governance, strategy, and technology. For issuers, Sarbanes-Oxley adds governance duties the auditor must understand, including the audit committee's authority over the auditor and management's certifications.

Strategy versus plan
The strategy covers scope, reporting objectives, key factors that direct the team's efforts, and resources. The plan covers direction and supervision, risk assessment procedures, and further audit procedures at the assertion level.
AU-C 300.08-.09
Audit committee authority
An issuer's audit committee is directly responsible for appointing, compensating, and overseeing the auditor, and it must set up procedures to receive complaints about accounting matters.
Sarbanes-Oxley Act sec. 301
Officer certifications
The CEO and CFO certify each periodic report, including that they are responsible for internal controls and have evaluated them.
Sarbanes-Oxley Act sec. 302
Internal control reporting
Management reports on internal control over financial reporting as of fiscal year-end, and the issuer discloses whether it has a code of ethics for senior financial officers and a financial expert on the audit committee.
Sarbanes-Oxley Act secs. 404, 406, 407

Internal control, IT and service organizations

The system of internal control has five components, matching the COSO framework, and every system has inherent limitations such as collusion and management override. The auditor distinguishes general IT controls, which support the IT environment as a whole, from information-processing controls that act on individual transactions. When an entity outsources processing, the auditor uses the service organization's SOC 1 report and considers the controls the user entity itself is expected to operate.

Five components
The five components are the control environment, the risk assessment process, the process to monitor the system, the information system and communication, and control activities.
AU-C 315.12
General IT controls
General IT controls cover managing access, managing program and other changes, and managing IT operations.
AU-C 315.12; AU-C 315 appendix F
Type 1 versus type 2
A type 1 report covers the description and design of controls as of a date. A type 2 report adds operating effectiveness over a period and is the one that supports reliance on controls.
AU-C 402.08, .16-.17
User auditor duties
The user auditor evaluates complementary user entity controls and does not refer to the service auditor in an unmodified opinion.
AU-C 402.14, .21

Materiality and the risk of material misstatement

Materiality for the financial statements as a whole starts from a benchmark and a percentage the auditor chooses, and performance materiality is set lower to allow for misstatements that go undetected. Under SAS No. 145, the auditor assesses inherent risk and control risk separately at the assertion level. Inherent risk is placed on a spectrum using inherent risk factors, and risks close to the upper end are significant risks. Fraud risks and the risk of management override call for specific responses.

Benchmarks
Common benchmarks are profit before tax, revenue, gross profit, expenses, equity, and net assets. A normalized or less volatile benchmark may be better when profit swings.
AU-C 320.A7-.A8
Inherent risk factors
The inherent risk factors are complexity, subjectivity, change, uncertainty, and susceptibility to management bias or fraud. They place a risk on the spectrum of inherent risk.
AU-C 315.12
Control risk
If the auditor will not test operating effectiveness, control risk is assessed at the maximum. Controls over significant risks must be tested in the current period if the auditor relies on them.
AU-C 315.38; AU-C 330.14-.15
Fraud presumptions
Revenue recognition is presumed to carry fraud risk, and the presumption is rebuttable only with documented reasons. Management override is present in every entity and always requires journal entry testing, a review of estimates for bias, and an evaluation of significant unusual transactions.
AU-C 240.26, .31-.32, .46
Substantive floor
Substantive procedures are required for each relevant assertion of each significant class, balance, and disclosure, however effective controls prove to be.
AU-C 330.18

Using others and specific risk areas

The auditor may use the work of internal auditors and specialists but keeps sole responsibility for the opinion. Laws and regulations fall into two groups, each with its own required procedures. Accounting estimates call for attention to management bias, and related parties call for alertness to relationships management has not disclosed. For entities that receive federal awards, the Uniform Guidance determines when a single audit is required and how major programs are selected.

Internal audit
Internal audit's work cannot be used if the function lacks objectivity, lacks competence, or lacks a systematic and disciplined approach. The auditor uses less of it as judgment and risk increase.
AU-C 610.14, .17
Specialists
The auditor evaluates the competence, capabilities, and objectivity of both its own specialists and management's specialists.
AU-C 620.09; AU-C 501.27
Two groups of laws
For laws with a direct effect on amounts, the auditor obtains sufficient appropriate evidence about those amounts. For other laws, the auditor inquires and inspects correspondence with regulators.
AU-C 250.06, .13-.14
Single audit trigger
An entity that spends $1,000,000 or more of federal awards in a year needs a single audit or, if it qualifies, a program-specific audit.
2 CFR 200.501
Major programs
Type A thresholds scale with total expenditures, and major programs must cover at least 40 percent of federal expenditures, or 20 percent for a low-risk auditee.
2 CFR 200.518, 200.520

Keep going: the full CPA Exam — Auditing and Attestation (AUD) guide covers every section of the exam. CPA AUD Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Studying in order?

Practice stays free. The full CPA Exam — Auditing and Attestation (AUD) study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Report